ISO 27001 Certification Cost: A Three-Year View

Most ISO 27001 cost guides quote a year-one number. That is misleading, because certification operates on a three-year cycle: initial certification, then surveillance audits in years two and three, then full recertification. Budgeting for year one alone means budgeting for less than half the commitment.

Three Buckets

Implementation. Closing gaps between where you are and what the standard requires. Consultancies commonly quote five and six figures. Largest and most variable bucket.

Tooling and controls. Whatever you need to buy — logging, vulnerability management, endpoint protection, GRC platform, penetration testing.

Certification body fees. The accredited body that audits and issues your certificate. Priced by audit days, which scale with headcount and scope.

What Drives Certification Body Fees

CB pricing is more formulaic than people expect. Audit days are calculated primarily from headcount within the ISMS scope, adjusted for complexity: number of sites, whether development is in scope, regulatory context, and how much of your infrastructure is outsourced.

The practical consequence is that scope control is your main lever on CB cost. A tightly scoped ISMS covering one product and one site costs materially less to audit than an organisation-wide scope — and is often what your buyers actually asked for anyway.

Get quotes from several accredited bodies. Pricing varies, and so does auditor availability, which affects your timeline as much as your budget.

The Three-Year Picture

Year 1: implementation, tooling, Stage 1 and Stage 2 audits. By far the heaviest.

Year 2: surveillance audit — shorter and cheaper than Stage 2, but not free. Plus recurring tooling, penetration testing, and the internal cost of running the ISMS.

Year 3: second surveillance audit, same shape as year two.

Year 4: full recertification, similar in scale to the original Stage 2.

Add the ongoing operational load: internal audits, management reviews, risk reassessments, and corrective actions. An ISMS is a system you run, not a project you finish.

Internal Time

The cost that appears on no invoice and is frequently the largest. Someone has to build the risk assessment, write policies people will actually follow, run the internal audit programme, prepare management reviews, and coordinate two audit stages.

Many organisations appoint an ISMS manager for this, either as a dedicated role or a substantial portion of an existing one. Budget it explicitly.

Where You Can Reasonably Save

Scope tightly. The highest-leverage decision available. It reduces implementation, audit days, and ongoing maintenance simultaneously.

Reuse existing compliance work. If you have SOC 2, the control overlap is substantial — access management, change management, vendor risk, incident response. What SOC 2 does not give you is the management system layer: risk assessment method, SoA, internal audit programme, management review.

Run internal audit in-house. Internal audit must be objective, not external. Someone auditing a function they do not own qualifies.

Buy a gap assessment, not a full implementation engagement. Knowing precisely what to fix is often the expensive part; fixing it is frequently work your team can do.

False Economies

A non-accredited certification body produces a certificate sophisticated buyers will reject. Template ISMS documentation that does not reflect how you actually operate fails at Stage 2, where auditors interview staff. And a scope so narrow it excludes the product your customers buy defeats the purpose entirely.

Scoping Decisions With the Largest Price Impact

Scope drives implementation effort, audit days, and ongoing maintenance simultaneously, which makes it the highest-leverage cost decision available.

Organisational boundary. Whole company, one business unit, or one product team. Narrower means fewer people in scope and fewer audit days.

Physical sites. Multi-site scopes may require sampling across locations, adding days and travel.

Development in scope. Including software development brings secure development controls into play and adds audit time.

Outsourcing. Heavily outsourced infrastructure can reduce audit days, though it increases supplier management obligations.

The constraint on narrowing: your certificate states its scope, and buyers read it. A scope that excludes the product your customer is buying is cheap and useless. Scope to what your buyers need covered, then no further.

Consultant, Platform, or In-House

Full-service consultancy. Highest cost, lowest internal load. The risk is an ISMS built around the consultant's templates rather than your operations, which surfaces at Stage 2 when auditors interview your staff.

Compliance platform plus internal effort. Middle cost. Platforms handle evidence collection, policy templates, and control tracking well. They do not build your risk assessment methodology or run your internal audit.

Gap assessment plus in-house implementation. Lowest external spend. You buy the expensive part — knowing precisely what to fix and how auditors will judge it — and do the implementation yourself. Works when you have someone who can own it.

The mistake is buying a full implementation engagement when what you needed was a gap assessment and a competent internal owner.

Questions for Certification Bodies

Get quotes from several, and ask each the same things:

  • How many audit days for Stage 1 and Stage 2 at our headcount and scope?
  • What are surveillance audit days and fees in years two and three?
  • What does recertification cost?
  • Is travel billed separately?
  • What is your current lead time to Stage 1?
  • Which accreditation body are you accredited under?

Accreditation is the one to verify rather than assume. A certificate from a non-accredited body costs less and gets rejected by exactly the buyers you sought certification for.

Scope First, Then Budget

Because scope drives every bucket, it is the first thing to settle. Our ISO 27001 risk assessment establishes scope and gives you a per-control gap picture, which is what you need before requesting CB quotes.

See also the certification timeline and implementation checklist.

FAQ

How much does ISO 27001 certification cost?

It splits across implementation, tooling, and certification body fees, and varies widely with headcount and scope. Consultancies commonly quote five to six figures for implementation alone; CB fees are priced by audit days.

What are certification body fees based on?

Audit days, calculated primarily from headcount within the ISMS scope and adjusted for complexity — number of sites, whether development is in scope, and how much is outsourced.

Are there ongoing costs after certification?

Yes. Surveillance audits in years two and three, full recertification in year four, plus recurring tooling, penetration testing, and the internal cost of running internal audits, management reviews, and risk reassessments.

Can I reduce cost if I already have SOC 2?

Meaningfully, yes. Control overlap is substantial. What SOC 2 does not provide is the management system layer — risk assessment method, Statement of Applicability, internal audit programme, and management review — which is where the remaining work sits.

Do I need a consultant for ISO 27001?

Not necessarily. Many organisations use a consultant for the gap assessment and risk assessment methodology, then implement in-house. Note that a consultant who builds your ISMS generally cannot also serve as your certification auditor.

Get your pentest quote today

Manual & AI Pentesting for SOC2, HIPAA, PCI DSS, NIST, ISO 27001, and More